# Index Pattern Matching

**URL:** <https://discuss.elastic.co/t/index-pattern-matching/63516>\
**Category:** Kibana\
**Created:** [October 20, 2016, 2:02pm UTC](https://discuss.elastic.co/t/index-pattern-matching/63516 "2016-10-20T14:02:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tgdesrochers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgdesrochers/32/51322_2.png) [@tgdesrochers](https://discuss.elastic.co/u/tgdesrochers)\
**Post date:** [October 20, 2016, 2:02pm UTC](https://discuss.elastic.co/t/index-pattern-matching/63516/1 "2016-10-20T14:02:15Z")

</div>

I am having an issue with index patterns in Kibana 4.5. I had an index pattern named _bro_, I deleted the index pattern then tried to recreate it but I am getting:

"Unable to fetch mapping. Do you have indices matching the pattern."

The part I am scratching my head at is I had this pattern working right before trying to recreate it.

Currently in my cluster I have multiple indices that contain the word "bro" mostly it shows up as "something-bro-something". I have tried matching index pattern \* as well but I get the same "Unable to fetch mapping. Do you have indices matching the pattern." How can I match this pattern? Is there something that would preclude me from matching _bro_ or \*?

I've tried in sense to look for the _bro_ index pattern and it is successful:

GET \_cat/indices/_bro_

So why is it that kibana will not locate it?

---

<div class="post-metadata">

**Author:** ![bevacqua](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bevacqua/32/10312_2.png) [@bevacqua](https://discuss.elastic.co/u/bevacqua)\
**Post date:** [October 20, 2016, 5:59pm UTC](https://discuss.elastic.co/t/index-pattern-matching/63516/2 "2016-10-20T17:59:51Z")

</div>

Tim, thanks for reporting this.

Could you try doing a `GET *bro*/_mapping/field/*` against Elasticsearch and paste the outputs here?

---

<div class="post-metadata">

**Author:** ![tgdesrochers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tgdesrochers/32/51322_2.png) [@tgdesrochers](https://discuss.elastic.co/u/tgdesrochers)\
**Post date:** [October 23, 2016, 2:32pm UTC](https://discuss.elastic.co/t/index-pattern-matching/63516/3 "2016-10-23T14:32:11Z")

</div>

Sorry for the delay. I ran the query and the output is quite large. I can  
attach a doc or just paste a sample.

```
GET localhost:9200/*bro*/_mapping/field/*?pretty
{
  "SANITIZED-bro-SANITIZED-2016.10.08" : {
    "mappings" : {
      "exploitkit" : {
        "IP.SRC.GEOIP.CC" : {
          "full_name" : "IP.SRC.GEOIP.CC",
          "mapping" : {
            "CC" : {
              "type" : "string",
              "fields" : {
                "raw" : {
                  "type" : "string",
                  "index" : "not_analyzed",
                  "ignore_above" : 256
                }
              },
              "analyzer" : "simple"
            }
          }
        },
        "HTTP.REQUEST._FULL.title" : {
          "full_name" : "HTTP.REQUEST._FULL.title",
          "mapping" : {
            "title" : {
              "type" : "string"
            }
          }
        },
        "WHOIS.DAYS_SINCE_CREATION" : {
          "full_name" : "WHOIS.DAYS_SINCE_CREATION",
          "mapping" : {
            "DAYS_SINCE_CREATION" : {
              "type" : "float"
            }
          }
        },
        "DNS.SLACKSPACE.DATA.keywords" : {
          "full_name" : "DNS.SLACKSPACE.DATA.keywords",
          "mapping" : {
            "keywords" : {
              "type" : "string"
            }
          }
        },
        "SSL.HANDSHAKE.CIPHERSUITES.DATA.title" : {
          "full_name" : "SSL.HANDSHAKE.CIPHERSUITES.DATA.title",
          "mapping" : {
            "title" : {
              "type" : "string"
            }
          }
        },
        "JS.UNZIP.DATA.content_length" : {
          "full_name" : "JS.UNZIP.DATA.content_length",
          "mapping" : {
            "content_length" : {
              "type" : "integer"
            }
          }
        },
        "SSL.HANDSHAKE.EXTENSION.DATA.date" : {
          "full_name" : "SSL.HANDSHAKE.EXTENSION.DATA.date",
          "mapping" : {
            "date" : {
              "type" : "date",
              "format" : "strict_date_optional_time||epoch_millis"
            }
          }
        },
        "DATA.DATA.content" : {
          "full_name" : "DATA.DATA.content",
          "mapping" : {
            "content" : {
              "type" : "string"
            }
          }
        },
        "HTTP.CONTENT.HASH" : {
          "full_name" : "HTTP.CONTENT.HASH",
          "mapping" : {
            "HASH" : {
              "type" : "long"
            }
          }
        },
        "DATA.DATA" : {
          "full_name" : "DATA.DATA",
          "mapping" : {
            "DATA" : {
              "type" : "attachment",
              "fields" : {
                "content" : {
                  "type" : "string"
                },
                "author" : {
                  "type" : "string"
                },
                "title" : {
                  "type" : "string"
                },
                "name" : {
                  "type" : "string"
                },
                "date" : {
                  "type" : "date",
                  "format" : "strict_date_optional_time||epoch_millis"
                },
                "keywords" : {
                  "type" : "string"
                },
                "content_type" : {
                  "type" : "string"
                },
                "content_length" : {
                  "type" : "integer"
                },
                "language" : {
                  "type" : "string"
                }
              }
            }
          }
        },
        "SSL.HANDSHAKE.RANDOM_BYTES.name" : {
          "full_name" : "SSL.HANDSHAKE.RANDOM_BYTES.name",
          "mapping" : {
            "name" : {
              "type" : "string"
            }
          }
        },
        "JS.ENG.SCORE" : {
          "full_name" : "JS.ENG.SCORE",
          "mapping" : {
            "SCORE" : {
              "type" : "double"
            }
          }
        },
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:35pm UTC](https://discuss.elastic.co/t/index-pattern-matching/63516/4 "2017-07-06T13:35:59Z")

</div>


